The Trojan Contact: Konni APT Hijacks KakaoTalk to Turn Victims into Attackers
ID: 5560f2ba-fd37-5b94-84fb-4adda7f09e04
STIX ID: report--5560f2ba-fd37-5b94-84fb-4adda7f09e04
Feed Name: securityonline.info
Threat Score
Konni APT is conducting a sophisticated multi-stage campaign that begins with spear-phishing LNK files which execute PowerShell to deploy decoys and download AutoIt and multiple RATs (EndRAT, RftRAT, RemcosRAT), establishes persistence via a frequent scheduled task, and then abuses compromised KakaoTalk PC sessions to send malicious files to trusted contacts, enabling account-based secondary distribution and broader propagation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
